cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
696
Views
0
Helpful
11
Replies

ASA redundant connection issue

mohammad saeed
Level 5
Level 5

Hi Guys,

 

I have one ASA connect to core with one interface (inside interface) I need to add another connection from the same ASA to other core for redundancy.

 

Can I do that? or not?

 

Thanks for all.

 

Mohammad Saeed

1 Accepted Solution

Accepted Solutions

Ji-Won Park
Level 1
Level 1

Hi Mohammad,

 

Of course you can do that. However, you need to know how the core switches are designed - it would be a different setup between VSS or HSRP/VRRP environment. If you have them stacked or VSSed, then you can do MEC to ASA primary bundling two ports into one channel (2Gb).

Hope this helps

 

g1

View solution in original post

11 Replies 11

Ji-Won Park
Level 1
Level 1

Hi Mohammad,

 

Of course you can do that. However, you need to know how the core switches are designed - it would be a different setup between VSS or HSRP/VRRP environment. If you have them stacked or VSSed, then you can do MEC to ASA primary bundling two ports into one channel (2Gb).

Hope this helps

 

g1

Hi Ji Won Park,

 

Thanks for helping me.

 

Yes I have VSS between them, could you suggest me a link which show me how to configure that in ASA and core 6509-e?

 

 

Thanks

 

Mohammad

Hi,

 

I got it through this link : 

http://www.cisco.com/c/en/us/td/docs/security/asa/asa93/configuration/general/asa-general-cli/interface-basic.html#15142

 

But I want to ask, which one is better to create redundant link or Etherchannel?

 

Thanks,

 

Mohammad

Hi Mohammad, Again, it depends on your ASA design. Is it active/active or active/standby? If its active/standby mode then you would want to do EtherChannel as you get link redundancy and both links will be in forwarding mode from Active ASA perspective. g1

Hi Ji Won,

 

I have One ASA and two 6509-e cores, So I think it's better to create an etherchannel?! Am I right?

 

Thanks a lot,

 

Mohammad

Yes sir, it would be one switch to one asa logically since your cat6ks are VSSed. Very simple design - you shouldn't have any issues with that. g1

Got it. 

 

Many thanks to you :-)

No problem. I'm glad it was helpful! :)

I have another issue with ping from GW to core.

 

I have this scenario (GW------ASA-------Core) I can ping between ASA+GW and ASA+core but I can't ping between Core + GW!

 

What is the problem?

 

Thanks.

Mohammad, please start the new thread for the new question. Thanks g1

Thanks, Here it is: https://supportforums.cisco.com/discussion/12549546/asa-firewall-connectivity

 

Review Cisco Networking for a $25 gift card